MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Kaseya VSA supply‑chain ransomware hits MSPs and customers

On 02/07/2021, REvil exploited a zero‑day in KASEYA’s VSA remote management software to distribute ransomware through dozens of MSPs to downstream businesses. Kaseya shut down VSA SaaS and advised on‑prem customers to take servers offline. Sweden’s COOP closed about 800 stores due to POS outages. REvil demanded $70M for a universal decryptor; Kaseya later obtained a universal decryptor from a trusted third party.

88

Estimated severity

88 / 100

88

Source reliability

88 / 100

Approximate Date

02/07/2021

Targeted Company

KASEYA

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

COOP (Sub-tier supplier)VISMA (Software vendor)

Geographic Impact

Country Targeted Company

United States

USA

Other Affected Countries

Sweden

SWE

Target country

United States

Affected countries

United StatesSweden

Impacted regions

Europe · SwedenNorth America · United States

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Service unavailabilityDownstream customer disruptionOperational disruption

Affected sectors

Technology & IT ServicesRetail

Affected departments

Information Technology

Attack Profile

Attack types

RansomwareSoftware supply chain compromiseExploitation of vulnerabilityZero-day exploitationSQL injection

Attributed threat actors

REVIL

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.